CSI 3004,552.58 0.10%
Hang Seng25,213.31 0.46%
Shanghai3,942.09 0.02%
CNY/USD6.7078 0.18%
FEATURE

9/3/2026 · 9 min read · 硅基观察Pro

AI Unlocks Third Major Commercial Scenario as Performance Surges and Stock Prices Double

Half a year ago, the market was still worried that AI would cannibalize SaaS.

By 2026, cybersecurity had become one of the strongest sectors on the US stock market.

Within the year, the US-listed cybersecurity ETF CIBR rose by over 40%. Individual stocks were even more striking, with Fortinet surging 117.6%, Palo Alto Networks climbing 107.9%, and CrowdStrike soaring 94.5%, nearly doubling in value.

The reason is simple: the deeper AI penetrates into enterprises, the more security issues arise.

Agents, APIs, and machine identities are increasing, rapidly expanding the attack surface; meanwhile, hackers are also using AI to accelerate vulnerability discovery and write attack scripts.

The result is that AI is on the one hand reducing the value of many software products, while on the other hand driving up security budgets.

And now, this logic has started to pay off in terms of performance. In the latest earnings season, CrowdStrike and Okta surged 20.5% and 28.6% after reporting earnings, while Cloudflare and Netskope also rose by more than 10%.

The logic behind the surge in cybersecurity stocks lies in the fact that the security demands brought about by AI are being converted into real orders, annual recurring revenue (ARR), and higher growth expectations.

To put it bluntly, after coding and video, network security is very likely to become the third scenario in AI applications to achieve substantial revenue.

Today, let's take a look at CrowdStrike and break down how this round of AI security opportunities came about.

Doubao Sees 51% YoY ARR Growth, Sets New Record

Speaking of CrowdStrike, you may not be very familiar with it.

But you must recall the incident two years ago in which 8.5 million Windows devices crashed simultaneously with a blue screen.

That's right, CrowdStrike was the "culprit" behind the incident.

The company initially focused on endpoint security, which simply put, involves protecting devices such as employees' computers and servers within an enterprise. Later on, it gradually expanded into areas including identity security, cloud security, and SIEM.

By the second quarter of this year, CrowdStrike's revenue was $1.47 billion, up 26% year-over-year.

But what really drove the stock price to surge 20% in a single day was not revenue, but rather the sudden explosion in new orders.

In the first quarter, CrowdStrike's net new ARR was $256 million, up 32% year-over-year. By the second quarter, this number jumped to $333 million, up 51% year-over-year, setting a company record.

Meanwhile, the quarter-end ARR reached $5.84 billion, up 25% year-over-year, marking a rebound from the 24% growth rate in the first quarter. The company even raised its full-year net new ARR growth guidance by 630 basis points to 34%.

This is interesting. A company with nearly $6 billion in annual recurring revenue (ARR) is actually seeing an acceleration in new ARR growth.

So, how does AI security become a source of revenue for CrowdStrike? The impact is mainly in two aspects.

The first category is new business brought about by AI, as companies begin to spend money specifically to protect their AI systems.

CrowdStrike's representative product is AIDR, or AI Detection and Response, which is responsible for discovering which AI tools are being used within an enterprise, which data is being sent to models, and whether there are any leaks of sensitive information.

At the end of the second quarter, AIDR's ARR increased by nearly three times quarter-over-quarter. Although no absolute scale was provided, a more direct signal came from customer orders.

According to disclosures on CrowdStrike's Q2 FY2027 earnings call, one of the world's largest banks purchased AIDR as part of an eight-figure dollar Falcon Flex contract to gain visibility into AI usage and prevent data leakage.

In other words, AI security has transitioned from trial and budget discussions to formal procurement by large enterprises.

The second category is where AI has expanded the company's original traditional businesses.

The most typical example is identity security, where in the past, companies focused on preventing employee account theft.

However, once Agents enter the enterprise, the situation becomes complicated. For an AI Agent to truly assist a company, it needs to log in to systems, call databases, access files, and even operate CRM and ERP systems, just like an employee. Each Agent may correspond to an API Key, service account, and machine identity. The more Agents a company deploys, the more "digital identities" it needs to manage and protect.

This directly expands CrowdStrike's identity security market. In the second quarter, the company's identity security ARR reached $585 million, up approximately 34% year-over-year.

Cloud security follows similar logic, as the majority of large model training, inference, and AI applications currently run on the cloud, driving up demand for cloud security. In the second quarter, CrowdStrike's cloud security ARR exceeded $905 million, representing a 29% year-over-year increase.

Of course, aside from increased demand, CrowdStrike's growth is also attributed to its unique procurement approach.

In 2023, CrowdStrike launched a flexible procurement model - Falcon Flex.

Unlike traditional network security software, which typically follows a "one product, one budget" sales model, the Falcon Flex model allows customers to first commit to a total budget, and then activate different Falcon modules as needed, without having to go through a lengthy approval and procurement process for each additional product.

This model is particularly suited to the AI era, as the speed at which AI creates demand has surpassed that of traditional corporate procurement processes. Today, a company may require identity security, but a few months later it may also need to add AIDR and cloud security, yet traditional procurement processes have not accelerated in tandem.

With this model, the ARR of the Flex customer base reached $229 million in the second quarter, representing a year-over-year increase of 101%, with the number of customers exceeding 2,900. After switching to Flex, the average ARR of ordinary customers increased by more than 40%.

So when you connect the entire chain, it's actually very clear:

AIDR has created a new AI security budget, with identity security and cloud security taking on the incremental expansion brought by AI, and Falcon Flex is further accelerating the conversion of these new demands into ARR.

Why Large Models Struggle with Cybersecurity

Earnings from CrowdStrike and other cybersecurity firms have belied the market's concerns from the first half of the year.

In February this year, Anthropic launched Claude Code Security, which can directly scan the entire codebase, identify high-risk vulnerabilities, and provide repair suggestions.

The first trading day after the news, cybersecurity stocks plummeted collectively, with Tenable falling 11.85%, and CrowdStrike and Zscaler both dropping by around 11%.

At the time, everyone was worried: if AI can find vulnerabilities, review code, and conduct security analyses on its own, will companies still need to spend so much money buying professional security software?

But half a year has passed, and the result is almost the opposite.

Most leading cybersecurity companies have reached new highs for the year, with the top 10 holdings of the HACK cybersecurity ETF averaging a year-to-date gain of 57%. The only exception is Zscaler, which is still being impacted by the frequent departure of its executives.

So the question arises, why can't large models replace network security?

First, the value of the entry point.

Palo Alto and Fortinet, these traditional security companies, have products with different forms, but they share one thing in common: they have long been deeply deployed in enterprise IT systems, and have long held first-hand security data.

Taking CrowdStrike as an example, its most crucial entry point is the Falcon Sensor.

After purchasing CrowdStrike, companies install this lightweight program on employee computers, servers, and other endpoint devices. Once installed, the Sensor runs continuously in the background, recording process launches, file changes, account logins, and network connections on the devices.

For instance, if an employee's account suddenly logs into the server in the middle of the night, then launches an abnormal program, reads a large number of files, and transmits data to an unfamiliar address, CrowdStrike can see this entire sequence of behavior in real-time and send the data back to the Falcon platform for analysis and judgment.

This is also a key advantage that traditional security companies have in the AI era. Large models can certainly be responsible for analysis and judgment, but the prerequisite is that they must first obtain this data. However, this ability to implement and gather data is precisely what model companies are not good at.

Second, it is a set of execution systems that have been trusted, authorized, and constrained by enterprises.

Discovering an attack is just the first step for security systems, and what's more important is to stop the attack.

Isolating servers, terminating malicious processes, banning accounts, and running repair scripts are all high-privilege operations in a production environment. If executed incorrectly, they may directly cause business interruptions.

This requires the system to first clearly define the boundaries of authority, ensuring that each operation is completed within predetermined rules. For high-risk actions, they are handed over to humans for confirmation, and a complete record is left for subsequent tracing.

This is also where the difficulty lies for OpenAI and Anthropic in moving directly into enterprise security. They not only need access to real-time endpoint data, but also high-risk permissions such as isolating machines and killing processes, before filling out the full permission, approval, audit, and governance framework. Getting to that point effectively means rebuilding an entire enterprise security platform from scratch—and the cost of that is self-evident.

In contrast, CrowdStrike has integrated these capabilities into its Falcon platform, where permissions, device scope, response strategies, and actual execution are separate, and AI can participate in judgment but can only act within the boundaries pre-set by the enterprise.

More than two points, the judgment that "large models will directly disrupt the network security industry" now seems a bit simplistic.

Currently, the relationship between large models and network security companies appears to be more cooperative and competitive, rather than simply substitutive.

On the one hand, large models are rapidly taking over the "brain work" in security.

Vulnerability analysis, code review, and alert evaluation, tasks that were previously highly dependent on security experts, are now being taken over by models. In April this year, CrowdStrike integrated Claude Opus 4.7 into Falcon for vulnerability discovery and repair.

On the other hand, the deeper the model is applied in real production environments, the stronger its dependence on traditional security systems becomes.

In July this year, when OpenAI was testing the Cyber model, the model, which was originally restricted to an isolated environment, found a vulnerability on its own and gained access to the internet, and then entered Hugging Face's real system. After the incident, OpenAI also invited external security consultants, including CrowdStrike, to participate in the investigation.

This matter is quite interesting.

OpenAI is providing CrowdStrike with a more powerful "brain", while CrowdStrike is helping OpenAI keep these increasingly powerful "brains" in check.

This may be the more realistic change in the cybersecurity industry in the AI era.

In the past, the core value of cybersecurity companies lay largely in their ability to "discover threats better than others." However, as model capabilities continue to strengthen, pure analytical capabilities will become increasingly inexpensive. The truly scarce resources are shifting downward, transforming into data, permissions, and execution systems.

The value of cybersecurity companies will also shift towards greater depth, becoming more like the "control layer" of the enterprise AI era.

One end connects increasingly intelligent models, the other end connects real computers, servers, identities, and cloud environments, needing to put AI capabilities in while ensuring these capabilities always operate within boundaries acceptable to enterprises.

This is what the market is really pricing in behind CrowdStrike's latest surge: AI is making some of the security company's capabilities cheaper, while also turning the security platform itself into a necessary gateway for AI to enter the real world.